UK GDPR (UK General Data Protection Regulation)
Chapter IV: Controller and processor – UK GDPR (UK General Data Protection Regulation)

UK GDPR (UK General Data Protection Regulation) Art.32: Article 32 Security of processing

Controllers and processors must implement technical and organisational measures ensuring security appropriate to the risk, taking into account the state of the art, costs, the nature and purposes of processing and the risks, including as appropriate pseudonymisation and encryption, the ongoing confidentiality, integrity, availability and resilience of systems and services, the ability to restore availability and access in a timely way after an incident, and a process for regularly testing, assessing and evaluating the measures. The assessment must weigh the risks of accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access. Codes or certification may help demonstrate compliance, and anyone acting under the controller's or processor's authority must process data only on instructions.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 4 controls across 2 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • 1.16 1.16 Security of monitoring data: risk-based measures, need-to-know access, trained staff, and responsibility for processors and tools
  • 3.10 3.10 Data loss prevention and traffic monitoring: least invasive means, a DPIA, and blocking with review as an alternative
  • 4.7 4.7 Biometric security: risk-appropriate measures; templates kept only as needed, refreshed, non-reversible and stored apart
  • P.12 P.12 Secure storage and viewing: restricted access, encryption or equivalents, secure cloud and transfers, monitors visible only to authorised staff

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Chapter IV: Controller and processor – UK GDPR (UK General Data Protection Regulation)

Query this from an agent

The graph holds this control, the 4 it maps to, and the evidence behind each claim, over MCP and REST.